Dipoll Privacy Policy
Last updated: July 16, 2026 · Effective: July 16, 2026
Dipoll ("Dipoll," "we," "us") operates the Dipoll social polling app and the website at
https://dipoll.org. This policy explains what we collect, why, who we share it with, and the
choices you have. It reflects what the app actually does today; if that changes, we will update
this policy and the "Last updated" date.
Contact: Dipoll · support@dipoll.org
1. Summary
Dipoll is a social product: you create an account, make and answer polls, vote, comment, send
direct messages, and explore results by geography and demographics. To do that we collect the
account details you give us, the content you post, the demographic and location data you choose
to provide, and limited technical and usage data from your device. We use Twilio to verify your
phone number, Apple and Google to deliver push notifications and (optionally) to let you sign
in, Google services for maps and optional AI poll summaries, and we host on Amazon Web Services.
We do not sell your personal information. You can delete your account and its data from
inside the app at any time.
2. Data we collect
Everything below is collected by the current app, grouped by source.
2.1 Account & authentication (you provide)
- Username (required) and email address (required at sign-up).
- Password — stored only as a salted hash; we never store or log your plaintext password.
- Phone number — collected during signup and verified via SMS.
- Email and phone verification codes and their expiry timestamps (short-lived).
- If you use Sign in with Apple or Google, we receive a verified email address (and, from
Google, a display name) from that provider's identity token to create or match your account. - Account timestamps (date joined) and account settings (e.g. your private-account setting).
2.2 Profile & demographics (optional — you choose what to provide)
Dipoll's insights features let you self-describe. All of these are optional profile fields:
age, gender identity, race/ethnicity, marital status, family size, education level, income
level, employment status, occupation, religion, nationality, languages spoken, sexual
orientation, disability status, health status, homeownership status, veteran/military status,
migration status, political affiliation / ideology / party, parental status, pet ownership,
living situation, housing type, vehicle ownership, dietary pattern, physical activity level, a
free-text location, and a short bio.
Several of these are sensitive categories of data under privacy laws such as the GDPR
(for example race/ethnicity, religion, health, disability, sexual orientation, and political
views). We collect them only if you enter them, and only to power the demographic
breakdowns of poll results that you and other users see. By filling in these fields you
consent to that use. You can leave any of them blank, change them, or clear them at any time
in Edit Profile.
- Profile picture — if you set one (chosen from your photo library or camera).
- Geographic profile fields — country, state/region, and postal code, used to place you on
the World View map and in country/region breakdowns. - Social graph — the lists of accounts you follow, that follow you, and that you have
blocked.
2.3 Content you create
- Polls you author: the prompt, options, any attached images, privacy setting, and poll
timing. - Votes you cast, including the option chosen and a timestamp. Votes may be marked
anonymous. - Comments and replies, comment likes, poll likes, shares, quote-polls, and reposts.
- Direct messages (DMs) and group chats: message text, image attachments, any poll you
share into a conversation, and read-receipt timestamps. - Collections and archives of polls you organize.
- Reports you submit about content (the reason and the reported item).
2.4 Location data
- Precise coordinates (latitude/longitude) are stored with each poll you create and each
vote you cast, along with a human-readable place name for polls. This powers the "nearby
polls" feed and the geographic result maps. - The app requests location permission on your device (iOS "When In Use"; Android fine and
coarse location) to center the map, show nearby polls, and optionally attach a place to polls
you create. You can decline or revoke this permission at any time in your device settings.
Because location is attached to poll and vote records, the general area you post or vote from
may be reflected in geographic result breakdowns. Anonymous votes are not attributed to you
in poll results.
2.5 Photos & camera
- We access your photo library and camera only when you choose a profile picture, add an
image to a poll, or attach an image to a message. We store the images you upload; we do not
scan your library.
2.6 Push notification tokens
- If you enable notifications, we store your device push token (Apple APNs on iOS, Firebase
Cloud Messaging on Android), the platform, and your per-category notification toggles (DMs,
activity, comment replies). We keep a log of pushes sent to you (title, body, delivery
status, timestamp) to operate and debug the notification system.
2.7 Usage & technical data
- In-app usage analytics synced from the app: aggregated screen-visit counts, foreground
time, and per-screen hit counts. This helps us understand how the app is used. - IP address is recorded on internal moderation audit records when a moderation action is
taken. - Standard server logs generated by our hosting and web infrastructure.
2.8 What we do NOT collect
We do not collect your contacts, your full photo library, background or continuous location,
biometric identifiers, or payment card data (there is no in-app purchase flow today). We do not
run third-party advertising SDKs. If this changes, we will update this policy first.
3. How we use your data
- Provide the service: authenticate you, show and rank feeds, run polls and voting, deliver
DMs, and render maps and demographic/geographic result breakdowns. - Verify identity and ownership: email and SMS verification to reduce spam and duplicate
accounts. - Notifications: send the push notifications you've enabled.
- Safety & moderation: review reported content, enforce our Community Guidelines and Terms
of Service, and keep an internal audit log of moderation actions. - Analytics & improvement: understand aggregate usage to improve the product.
- AI poll summaries (optional feature): when AI insights are enabled, aggregate poll
content and results are sent to Google's Gemini API to generate a summary shown to viewers of
that poll. Your DMs are never sent to AI services. See §5.
4. Legal bases (GDPR / UK GDPR)
Where these laws apply, we rely on: performance of a contract (running your account and the
core features), legitimate interests (safety, moderation, and product analytics),
consent (optional profile and demographic fields, precise location, notifications, and any
sensitive categories of data), and legal obligation where applicable. You can withdraw
consent at any time by editing your profile, changing device permissions, or deleting your
account.
5. Third parties we share data with
We share only what each service needs to function. We do not sell personal information.
| Provider | Purpose | Data shared |
|---|---|---|
| Twilio (Verify API) | Phone number verification via SMS | Your phone number and the verification attempt |
| Apple Push Notification service (APNs) | iOS push delivery | Device push token, notification content |
| Google / Firebase Cloud Messaging (FCM) | Android push delivery | Device push token, notification content |
| Apple / Google Sign-In | Optional social login | Identity token → your verified email (and Google display name) |
| Google Maps Platform | Map tiles and geocoding for the map and nearby features | Location/map queries |
| Google Gemini (Generative AI) | Optional AI poll summaries | Aggregated poll prompt, options, and results (never your DMs) |
| Amazon Web Services | Hosting the backend and database | All app data is stored on our AWS-hosted infrastructure |
| Google (Gmail SMTP) | Sending verification and transactional email | Your email address and message content |
Each provider processes data under its own privacy terms.
6. Retention & deletion
- We keep your account data while your account is active.
- You can delete your account in the app (Settings → Delete account). Deleting your account
removes your user record; your polls, votes, messages, and push tokens are removed or
disassociated from you. Aggregate poll results (for example total vote counts) may persist in
anonymized form. - Some records may persist for a limited period for legal, security, or fraud-prevention
reasons (for example moderation audit logs), after which they are deleted or anonymized. - Verification codes are short-lived and cleared once used or expired.
To request deletion or a copy of your data outside the app, contact support@dipoll.org.
7. Your rights & choices
- In-app controls: edit or clear any profile or demographic field, set your account
private, block users, manage notification toggles, and delete your account. - Device controls: revoke location, camera, photo, or notification permissions in your OS
settings at any time. - GDPR/UK/EEA rights: access, rectification, erasure, restriction, portability, objection,
and the right to lodge a complaint with a supervisory authority. - California (CCPA/CPRA) rights: know, delete, correct, and opt out of "sale"/"sharing." We
do not sell or share personal information as those terms are defined. California residents
may also designate an authorized agent. - We honor these requests as required by law; contact support@dipoll.org.
8. Children
Dipoll is not directed to children under 16. We do not knowingly collect personal information
from anyone under 16. If you believe a child under 16 has provided us data, contact
support@dipoll.org and we will delete it.
9. Security
Passwords are stored only as salted hashes, the API requires authenticated token-based access,
and administrative surfaces are restricted server-side. No system is perfectly secure; if you
discover a vulnerability, please report it to support@dipoll.org.
10. International transfers
Data is stored on AWS infrastructure in the United States (AWS us-east-1, Northern Virginia).
If you access Dipoll from outside the United States, your data will be transferred to and
processed in the United States.
11. Changes to this policy
We will post changes here and update the "Last updated" date; material changes will be surfaced
in-app.
12. Contact
Dipoll · support@dipoll.org · https://dipoll.org